docs: plan PSD server deployment program
This commit is contained in:
@@ -0,0 +1,98 @@
|
||||
# PSD Server Project A — Acceptance Report
|
||||
|
||||
> Template only. Store detailed/raw evidence in the protected server evidence root. This report
|
||||
> must not contain passwords, tokens, cookies, keys, hashes of passwords, secret-file contents,
|
||||
> raw claims, patient-identifying data, or unbounded logs.
|
||||
|
||||
## Decision
|
||||
|
||||
- Result: `PROJECT_A_PASS` / `PROJECT_A_FAIL` / `PROJECT_A_PENDING`
|
||||
- Decision timestamp UTC:
|
||||
- Owner/reviewer:
|
||||
- Protected evidence path:
|
||||
- Evidence manifest SHA-256:
|
||||
|
||||
## Frozen identities
|
||||
|
||||
- ThothII source SHA:
|
||||
- Plan source SHA:
|
||||
- Workspace previous SHA:
|
||||
- Workspace multi-transport SHA:
|
||||
- Mac REST validation result/evidence reference:
|
||||
- Native `tht` version/build identity:
|
||||
- Core image ID/digest:
|
||||
- Frontend image ID/digest:
|
||||
- Qdrant image digest:
|
||||
- Ollama image digest:
|
||||
- Pi version/provider/model/thinking:
|
||||
|
||||
## Survey and legacy recovery
|
||||
|
||||
- Survey result/digest:
|
||||
- Legacy source/image identity:
|
||||
- Legacy backup location/checksum reference:
|
||||
- Legacy restart recipe verified: PASS/FAIL
|
||||
- Legacy stack stopped without deletion: PASS/FAIL
|
||||
- Production route closed: PASS/FAIL
|
||||
|
||||
## New installation
|
||||
|
||||
- Installation descriptor path:
|
||||
- Compose project:
|
||||
- Frontend loopback/private origin:
|
||||
- Optional private endpoint used: yes/no
|
||||
- Optional allowlist positive/negative result:
|
||||
- Service health result:
|
||||
- Doctor result:
|
||||
- Pi result:
|
||||
- Listener-boundary result:
|
||||
|
||||
## Authentication
|
||||
|
||||
- Mode: local
|
||||
- Admin/user separation:
|
||||
- Wrong-password generic failure:
|
||||
- Disable/enable:
|
||||
- Password/role/logout-all invalidation:
|
||||
- Remembered restart:
|
||||
- Logout:
|
||||
- CSRF/cross-origin rejection:
|
||||
- Manual guide result and reviewer:
|
||||
|
||||
## Workspace and data plane
|
||||
|
||||
- Workspace ID/revision:
|
||||
- Server transport: postgres_direct
|
||||
- Mac transport remains rest_api: PASS/FAIL
|
||||
- Supabase database name:
|
||||
- DWH schema: datawarehouse
|
||||
- Read-only role proof reference:
|
||||
- DWH connection diagnostics:
|
||||
- Qdrant collection contract:
|
||||
- Ollama model/dimensions:
|
||||
- Preprocess first run ID/result:
|
||||
- FK review digest/result:
|
||||
- Schema point count:
|
||||
- Evidence point/chunk count:
|
||||
- Preprocess idempotency result:
|
||||
- Effective configuration identity:
|
||||
|
||||
## F1-F8 session
|
||||
|
||||
- Approved sanitized question reference:
|
||||
- Session ID:
|
||||
- Owner identity type: local ordinary user
|
||||
- Resume tested:
|
||||
- F1-F8 result:
|
||||
- Finalized:
|
||||
- Final SQL read-only validation:
|
||||
- Persisted artifact/decision inventory:
|
||||
- No patient-identifying evidence retained: PASS/FAIL
|
||||
|
||||
## Rollback and hygiene
|
||||
|
||||
- New-installation backup/checksum reference:
|
||||
- Legacy rollback remains available:
|
||||
- Secret scan result:
|
||||
- Unrelated failures or pending items:
|
||||
- Reason for final decision:
|
||||
@@ -0,0 +1,108 @@
|
||||
# PSD Server Project B — Acceptance Report
|
||||
|
||||
> Template only. Store raw Authentik exports, database backups, browser traces, and server topology
|
||||
> only in protected server storage. Never retain passwords, provider/client secrets, API tokens,
|
||||
> cookies, raw claims, callback query strings, private keys, patient-identifying data, or unbounded
|
||||
> logs in this report.
|
||||
|
||||
## Decision
|
||||
|
||||
- Result: `PROJECT_B_PASS` / `PROJECT_B_FAIL` / `PROJECT_B_PENDING`
|
||||
- Decision timestamp UTC:
|
||||
- Owner/reviewer:
|
||||
- Protected evidence path:
|
||||
- Evidence manifest SHA-256:
|
||||
- Accepted Project A report digest:
|
||||
|
||||
## Frozen candidate
|
||||
|
||||
- ThothII source SHA:
|
||||
- Workspace SHA:
|
||||
- Core/frontend image identities:
|
||||
- Qdrant/Ollama image identities:
|
||||
- Pi provider/model:
|
||||
- Public origin:
|
||||
- Aritmolab source/deployment revision:
|
||||
|
||||
## Authentik
|
||||
|
||||
- Installed version:
|
||||
- Pre-change export reference/checksum:
|
||||
- Application name/ID:
|
||||
- Provider name/ID:
|
||||
- Issuer:
|
||||
- Callback path verified:
|
||||
- Grant types/scopes verified:
|
||||
- Direct groups claim shape verified:
|
||||
- User group name/ID:
|
||||
- Admin group name/ID:
|
||||
- Group-catalog service account name/ID:
|
||||
- Least-privilege result:
|
||||
- `auth check --json` result:
|
||||
- Interactive device check: PASS/FAIL/PENDING
|
||||
- No secret/raw claim in evidence: PASS/FAIL
|
||||
|
||||
## Supabase session storage
|
||||
|
||||
- Existing database name:
|
||||
- Session schema: thoth_sessions
|
||||
- Backup reference/checksum:
|
||||
- Migration result (`pending=[]`, `drifted=[]`):
|
||||
- Migration idempotency:
|
||||
- Runtime role security/RLS result:
|
||||
- Migrator absent from core:
|
||||
- PostgREST exposed schemas proof:
|
||||
- `thoth_sessions` not REST-exposed: PASS/FAIL
|
||||
- DWH `datawarehouse` privileges unchanged: PASS/FAIL
|
||||
|
||||
## Nginx, TLS, load balancer, and Aritmolab
|
||||
|
||||
- Nginx configuration file/revision:
|
||||
- `nginx -t` result:
|
||||
- Certificate subject/SAN/expiry metadata:
|
||||
- Certificate trust result:
|
||||
- Load-balancer route/health result:
|
||||
- Same-origin API/callback result:
|
||||
- SSE unbuffered result:
|
||||
- No double `auth_request`: PASS/FAIL
|
||||
- Sidebar source/link result:
|
||||
- Other virtual hosts unchanged: PASS/FAIL
|
||||
|
||||
## Human SSO and authorization
|
||||
|
||||
- Aritmolab login → sidebar → ThothII without second credential prompt:
|
||||
- Ordinary user permissions:
|
||||
- Administrator permissions:
|
||||
- No-role user result:
|
||||
- Extra unrelated group result:
|
||||
- Missing/malformed group negative result:
|
||||
- Forged-header result:
|
||||
- ThothII logout result:
|
||||
- Authentik SSO session behavior documented:
|
||||
- Provider/catalog controlled failure and recovery:
|
||||
- Manual guide result and reviewer:
|
||||
|
||||
## OIDC F1-F8 session and ownership
|
||||
|
||||
- Approved sanitized question reference:
|
||||
- Session ID:
|
||||
- OIDC principal reference (non-identifying):
|
||||
- F1-F8/final SQL result:
|
||||
- PostgreSQL manifest/artifact/decision persistence:
|
||||
- Resume/restart result:
|
||||
- Cross-user isolation result:
|
||||
- Admin cross-user result:
|
||||
- Chat/SSE ephemeral boundary:
|
||||
|
||||
## Rollback, cleanup, and hygiene
|
||||
|
||||
- Ingress-first rollback rehearsal:
|
||||
- Project A protected configuration available:
|
||||
- Authentik disable plan verified:
|
||||
- Additive schema rollback boundary verified:
|
||||
- Project A temporary endpoint removed:
|
||||
- Legacy stack stopped/unexposed:
|
||||
- Core/Qdrant/Ollama private:
|
||||
- Secret scan result:
|
||||
- Unrelated failures or pending items:
|
||||
- Reason for final decision:
|
||||
@@ -0,0 +1,151 @@
|
||||
# PSD Server — Survey Report
|
||||
|
||||
> Template only. The completed report and raw inventory remain in protected server storage. Do not
|
||||
> include passwords, tokens, cookies, private keys, password hashes, raw claims, full container
|
||||
> environments, patient-identifying data, or unbounded logs.
|
||||
|
||||
## Decision
|
||||
|
||||
- Result: `SURVEY_GO` / `SURVEY_NO_GO`
|
||||
- Timestamp UTC:
|
||||
- Operator:
|
||||
- Protected evidence path:
|
||||
- Report SHA-256:
|
||||
- Blocking unknowns:
|
||||
|
||||
## Host
|
||||
|
||||
- OS/version/kernel:
|
||||
- Architecture:
|
||||
- Docker/Compose versions:
|
||||
- CPU/RAM/free disk:
|
||||
- Approved service UID/GID:
|
||||
- Local terminal/CyberArk constraints:
|
||||
|
||||
## Legacy ThothII
|
||||
|
||||
- Source path/SHA/dirty state:
|
||||
- Compose/controller path and project:
|
||||
- Services/images:
|
||||
- Published ports:
|
||||
- Networks:
|
||||
- Volumes/binds:
|
||||
- Data/config/secret reference paths:
|
||||
- Current health:
|
||||
- Active sessions/users:
|
||||
- Recovery/maintenance state:
|
||||
- Backup procedure and owner:
|
||||
- Exact stop/start commands:
|
||||
|
||||
## New installation roots
|
||||
|
||||
- Adjacent source root:
|
||||
- Operator root:
|
||||
- Secret root:
|
||||
- Data root:
|
||||
- Pi-state root:
|
||||
- Workspace-registry root:
|
||||
- Backup root:
|
||||
- Protected evidence root:
|
||||
- Port reserved for Project A:
|
||||
|
||||
## Nginx, TLS, and load balancer
|
||||
|
||||
- Nginx version/config owner:
|
||||
- Relevant virtual-host/include files:
|
||||
- Current ThothII upstream:
|
||||
- Forwarded headers/SSE behavior:
|
||||
- Certificate subject/SAN/issuer/expiry:
|
||||
- Certificate generation/renewal owner:
|
||||
- Load-balancer owner/config surface:
|
||||
- Health check/TLS boundary/source addresses:
|
||||
- Temporary hostname allowlist possible: yes/no
|
||||
- Exact reload/rollback procedure:
|
||||
|
||||
## Aritmolab
|
||||
|
||||
- Public origin observed:
|
||||
- Source/deployment path and SHA:
|
||||
- Compose/network identity:
|
||||
- Sidebar file/line/link target:
|
||||
- Historical `.it`/`.com` discrepancy resolved as:
|
||||
- Build/test/deploy procedure:
|
||||
- Configuration owner:
|
||||
|
||||
## Authentik
|
||||
|
||||
- Installed version/image:
|
||||
- Deployment path/services:
|
||||
- Base URL/issuer conventions:
|
||||
- Existing Aritmolab application/provider pattern:
|
||||
- Groups relevant to ThothII:
|
||||
- Credential reference paths and usability:
|
||||
- Export/backup procedure:
|
||||
- API/OpenAPI version:
|
||||
- Required human help:
|
||||
|
||||
## Supabase/PostgreSQL
|
||||
|
||||
- Existing database name:
|
||||
- PostgreSQL/pooler/PostgREST components:
|
||||
- Direct container-to-database route:
|
||||
- TLS mode/CA reference:
|
||||
- Existing schemas:
|
||||
- Existing `thoth_sessions` state:
|
||||
- PostgREST exposed schemas:
|
||||
- Backup/restore mechanism:
|
||||
- Proposed runtime/migrator role names:
|
||||
- Role-creation owner:
|
||||
|
||||
## PSD DWH
|
||||
|
||||
- Database/schema:
|
||||
- Direct host/port from core:
|
||||
- Runtime role reference:
|
||||
- Read-only grant proof result:
|
||||
- TLS requirements:
|
||||
- REST binding retained for Mac:
|
||||
|
||||
## Workspace Git
|
||||
|
||||
- Remote/branch/access:
|
||||
- Current main SHA:
|
||||
- Server deploy-key scope:
|
||||
- Descriptor schema/transports:
|
||||
- Evidence/annotations state:
|
||||
- Curator with push authority:
|
||||
|
||||
## Pi, LLM, Qdrant, and Ollama
|
||||
|
||||
- Pi version/provider/model/thinking:
|
||||
- Credential reference:
|
||||
- LLM endpoint reachability:
|
||||
- Qdrant/Ollama image architecture support:
|
||||
- Capacity assessment:
|
||||
|
||||
## Topology
|
||||
|
||||
Describe the observed final flow and every trust boundary. Reference a protected diagram if the
|
||||
topology itself is considered sensitive.
|
||||
|
||||
## Intended changes by owner
|
||||
|
||||
| Owner/component | Exact files/objects | Project | Rollback |
|
||||
|---|---|---|---|
|
||||
| New ThothII | | A/B | |
|
||||
| Workspace curator | | A | |
|
||||
| Nginx | | A optional/B | |
|
||||
| Load balancer | | A optional/B | |
|
||||
| Aritmolab | | B | |
|
||||
| Authentik | | B | |
|
||||
| Supabase | | B | |
|
||||
|
||||
## GO/NO-GO rationale
|
||||
|
||||
- Verified old-stack rollback:
|
||||
- Verified secret custody:
|
||||
- Verified read-only DWH:
|
||||
- Verified configuration owners:
|
||||
- Verified resources:
|
||||
- Unresolved risks:
|
||||
- Final rationale:
|
||||
Reference in New Issue
Block a user